Operations

Day-two BRIDGE: the dashboard, the CLI, the API, and the service manager.

Dashboard tour

The embedded operations dashboard is a dark, Cloudflare-inspired ops console served by the daemon itself: no separate process. By default it listens on http://127.0.0.1:9090 (loopback only). Its views:

ViewWhat it shows
OverviewFleet at a glance: node count, leader, routes, and current handoff tier.
NodesEvery known member with its lifecycle state (Alive / Suspected / Dead / Recovered), endpoint, and priority.
MeshThe WireGuard overlay: mesh IPs, links, and connectivity between nodes.
RoutesStatic and Docker-discovered routes, their upstreams, and consistent-hash targets.
EventsReal-time event feed streamed over WebSocket: elections, handoffs, membership changes, failovers.
ConfigThe running configuration as loaded by the daemon.

CLI reference

The bridge CLI talks to the running daemon over its Unix socket (/tmp/bridge.sock, see [ipc]).

CommandDescription
bridge statusDaemon and fleet summary: uptime, role (leader/follower), membership counts.
bridge routesList all routes, static and discovered.
bridge add-routeAdd a route to the running daemon.
bridge remove-routeRemove a route from the running daemon.
bridge clusterShow cluster membership and each node's lifecycle state.
bridge inspect <domain>Inspect the route and upstream resolution for a hostname.
bridge replicasShow failover-duplication replicas and their placement.
bridge pingCheck that the daemon answers over the IPC socket.

Health endpoint

GET /health on the dashboard listener reports daemon health, suitable for load-balancer or monitoring checks:

curl -fsS http://127.0.0.1:9090/health

JSON API

The dashboard listener also serves a JSON API under /api/v1, plus a WebSocket stream for real-time events:

EndpointDescription
GET /api/v1/statusDaemon and fleet status.
GET /api/v1/nodesCluster members and lifecycle states.
GET /api/v1/routesConfigured and discovered routes.
GET /api/v1/meshWireGuard mesh topology.
GET /api/v1/eventsRecent events.
GET /api/v1/handoffCurrent handoff tier and state.
GET /api/v1/configRunning configuration.
WS /api/v1/streamReal-time event stream (the same feed the dashboard renders).

systemd management

The installer registers bridge.service:

systemctl status bridge     # service state
systemctl restart bridge    # pick up a config change
journalctl -u bridge -f     # follow daemon logs

The unit runs the daemon as the unprivileged bridge user with CAP_NET_BIND_SERVICE and CAP_NET_ADMIN: enough to bind ports 80/443 and configure WireGuard without full root.

Graceful shutdown

On stop or restart, the daemon's shutdown coordinator drains subsystems in order (ingress first, background workers last) and persists state to disk. A restarted node resumes from the last known fleet state instead of rejoining cold.

Upgrading

Re-run the installer. It downloads and verifies the new release, replaces the binary, and restarts the service. Your existing /etc/bridge/bridge.toml is never overwritten. Pin a specific version when you want a controlled rollout:

curl -fsSL https://bridgemesh.space/install.sh | sh
# or pin a version:
curl -fsSL https://bridgemesh.space/install.sh | BRIDGE_VERSION=v1.2.3 sh

Upgrade followers first and the leader last: the fleet re-elects a follower as leader, hands off the ingress, and the old leader rejoins after its upgrade.